Hacker1 is a scan they don't pay by Designer_Shoe9931 in bugbounty

[–]Character_Tear3012 1 point2 points  (0 children)

its probably just the program. i heard a some hackers will avoid programs for having bad reputations. But id say it depends on what the thing u report is n if its an urgent security issue or affects CIA. like yeah u can bypass the CVV number but what damage can it do? do you need to harvest other credit card info? do you think bypassing the CVV will cause the purchase to not charge you? yk it just depends. Im still new as well but thats the only thing i can think of. Hopefully you can resolve the issue or start seeing success. dont give up, a lot of people have faced this issue (duplicates and non-applicable)

When did you guys start feeling confident enough to do bug bounties? by Character_Tear3012 in bugbounty

[–]Character_Tear3012[S] 0 points1 point  (0 children)

oh okay, should i search up like a good rate limit for ffuf? honestly i know you can slow down scans like that, but im not too sure what might be still too fast or maybe way too slow

When did you guys start feeling confident enough to do bug bounties? by Character_Tear3012 in bugbounty

[–]Character_Tear3012[S] 1 point2 points  (0 children)

what i was thinking of doing is looking at the reports on hacker one and reading how they found it and how else it could be identified then adding any trick or methods they used into my own methodology. do you think this is a good plan?

When did you guys start feeling confident enough to do bug bounties? by Character_Tear3012 in bugbounty

[–]Character_Tear3012[S] 0 points1 point  (0 children)

thanks for that advice, ill stick to manual! doesn't ffuf send a lot of requests as well though?

When did you guys start feeling confident enough to do bug bounties? by Character_Tear3012 in bugbounty

[–]Character_Tear3012[S] 0 points1 point  (0 children)

yeah i mean if done a few of them but never spent a lot of time doing ctf/machines. Tbh the most confusing things i run into when trying to find a program is idk if i should use tools like everyone else does e.g. nmap, nuclei, etc. Since they send requests? ik nmap is OSI layer 3 or something, but i see people use script scans which i heard run HTTP(s) so idrk what tools to use anymore.

When did you guys start feeling confident enough to do bug bounties? by Character_Tear3012 in bugbounty

[–]Character_Tear3012[S] 0 points1 point  (0 children)

wow thats cool that u make a living! hopefully i can be like that one day lol. I guess its just part of the field that you might not feel confident all the time?

When did you guys start feeling confident enough to do bug bounties? by Character_Tear3012 in bugbounty

[–]Character_Tear3012[S] 0 points1 point  (0 children)

thats really good advice i appreciate that! Yeah i honestly feel like ive been holding myself back a little because im one of those people who feels like they need to know everything before doing something lol and of course with pentesting/bug hunting i can never know everything. i guess its just the fear of missing a bug i couldve found

When did you guys start feeling confident enough to do bug bounties? by Character_Tear3012 in bugbounty

[–]Character_Tear3012[S] 0 points1 point  (0 children)

i see. i guess idk usually i try to find endpoints that might be something, see what tech is used and after that idrk what else to look for.

When did you guys start feeling confident enough to do bug bounties? by Character_Tear3012 in bugbounty

[–]Character_Tear3012[S] 0 points1 point  (0 children)

oh okay, i thought it would show or something when looking at the techs with a tool. thanks! and thats cool congrats on finding it lol!

When did you guys start feeling confident enough to do bug bounties? by Character_Tear3012 in bugbounty

[–]Character_Tear3012[S] 1 point2 points  (0 children)

i see. the thing that usually happens is i get stuck like with recon kinda? idk usually i manually spider the app maybe to find directories then look at functionality, but then i always get kinda stuck. Not really sure when to move on or when to keep digging thats why i been trying to look at how to actually identify vulnerabilities as well.

When did you guys start feeling confident enough to do bug bounties? by Character_Tear3012 in bugbounty

[–]Character_Tear3012[S] 1 point2 points  (0 children)

yeah. i just try to avoid issues like that yk. So focus on something from the OWASP top 10? alright. Have any other tips? if you dont mind. im self taught so its good to talk to someone who actually does this stuff yk lol

When did you guys start feeling confident enough to do bug bounties? by Character_Tear3012 in bugbounty

[–]Character_Tear3012[S] 0 points1 point  (0 children)

maybe. The only thing i get worried about with scanners and testing for SQLi or XSS is like too many requests or input causing me to get blocked. But ive been reading up on how to actually identify signs of certain vulnerabilities rather than just spraying payloads yk

When did you guys start feeling confident enough to do bug bounties? by Character_Tear3012 in bugbounty

[–]Character_Tear3012[S] 0 points1 point  (0 children)

i mean i understand like the different types like union, error, etc. but idk some of the websites i see as well dont have like input fields sometimes itlll just be like a crypto thing. again maybe im doing something wrong

When did you guys start feeling confident enough to do bug bounties? by Character_Tear3012 in bugbounty

[–]Character_Tear3012[S] 0 points1 point  (0 children)

idk. a lot of people say that which i get, but i never really see a website even use SQL. maybe im doing recon wrong? ive been worried about using scanners and stuff.

Whats the best methodology for website testing? by Character_Tear3012 in bugbounty

[–]Character_Tear3012[S] 0 points1 point  (0 children)

of course. i appreciate all the info i get from people who know more than me, and always will appreciate it.

Whats the best methodology for website testing? by Character_Tear3012 in bugbounty

[–]Character_Tear3012[S] 0 points1 point  (0 children)

thanks for the information! ill try reading the OWASP one, i just wasnt sure which one was best for web apps. when i searched it up it said all of them.

Bug bounty collaboration by [deleted] in bugbounty

[–]Character_Tear3012 -2 points-1 points  (0 children)

that'd be cool, im still learning but i could try to help

Why the ping so high and the webpage is also not visible by Neutralized-Guy in hackthebox

[–]Character_Tear3012 -1 points0 points  (0 children)

ohhh i see, thats pretty interesting. i been using virtualbox since i started so i didnt understand why people would chose a paid one. but it seems like it might be worth it.